This discussion has been locked.
You can no longer post new replies to this discussion. If you have a question you can start a new discussion

Zugriff zwischen IPSEC VPN Client

Hallo zusammen,

wir greifen von mehreren Aussenstellen per Sophos IPSEC VPN Client auf das Büro zu.

Für eine neue Funktion(Software) benötigen wir direkten Zugriff zwischen den Remote-Arbeitsplätzen.

Über den IPSEC Client (IP aus IPSEC Pool) lassen sich die Aussenstellung nicht untereinander anpingen.

was beim SSL VPN Client (IP aus SSL Pool) problemlos funktioniert.

Im Firewall Log werden keine geblockten Pakete angezeigt.

Hat jemand ein Idee dazu?

Danke vorab

RP

 



This thread was automatically locked due to age.
Parents
  • Hallo Ronny,

    Erstmal herzlich willkommen hier in der Community !

    (Sorry, my German-speaking brain isn't creating thoughts at the moment. [:(])

    It's clearly a routing problem.  I haven't tried the following, but I think it might work:

    1. On the Internal Interface, define Additional Addresses "Ronny via VPN" and "Bob via VPN" as /32
    2. Create two NAT rules with automatic firewall rules:
      1. DNAT : Any -> Any -> Internal [Ronny via VPN] (Address) : to Ronny (User Network)
      2. DNAT : Any -> Any -> Internal [Bob via VPN] (Address) : to Bob (User Network)

    Now, when Bob and Ronny are connected to IPsec Remote Access, they should be able to connect via the other's Additional Address.

    Did that work?

    MfG - Bob (Bitte auf Deutsch weiterhin.)

Reply
  • Hallo Ronny,

    Erstmal herzlich willkommen hier in der Community !

    (Sorry, my German-speaking brain isn't creating thoughts at the moment. [:(])

    It's clearly a routing problem.  I haven't tried the following, but I think it might work:

    1. On the Internal Interface, define Additional Addresses "Ronny via VPN" and "Bob via VPN" as /32
    2. Create two NAT rules with automatic firewall rules:
      1. DNAT : Any -> Any -> Internal [Ronny via VPN] (Address) : to Ronny (User Network)
      2. DNAT : Any -> Any -> Internal [Bob via VPN] (Address) : to Bob (User Network)

    Now, when Bob and Ronny are connected to IPsec Remote Access, they should be able to connect via the other's Additional Address.

    Did that work?

    MfG - Bob (Bitte auf Deutsch weiterhin.)

Children
No Data